Live data from Hacker News

Building secure, scalable agent sandbox infrastructure

browser-use.com

11–19 of 19 posts

Re: Building secure, scalable agent sandbox infrastructure

#11
post #8

The billion engineers building sandbox tools at the moment are missing the point. Sandboxing doesn't matter when the LLM is vulnerable to prompt injection. Every MCP server you install, every webpage it fetches, every file it reads is a threat. Yeah you can sit there and manually approve every action it takes, but then how is any of this useful when you have to supervise it constantly? Even Anthropic say that this do…

Prompt injection is hard but I believe tractable. I've found that by having a canary agent transform insecure input into a structured format with security checks, you can achieve good isolation and mitigation. More at https://sibylline.dev/articles/2026-02-22-schema-strict-prom...

Re: Building secure, scalable agent sandbox infrastructure

#12
post #5

The first 3 “hardening” points are not great. Essentially it’s just: remove .py files an execute del os.environ[“SESSION_TOKEN“]? This doesn’t really sound very secure, there are a number of ways to bypass both of these. It’s just security through obscurity

Fair point, and you're right that those three steps alone aren't a security boundary. They're defense-in-depth, not the primary isolation.

The actual security model is the architecture itself: the sandbox runs in its own VM inside a private VPC. It has no AWS keys, no database credentials, no LLM API tokens. The only thing it can do is talk to the control plane, which validates every request and scopes every operation to that one session.

So even if you bypass all three hardening steps, you get a session token that only works inside that VPC, talking to a control plane that only lets you do things scoped to your own session. There's nothing to escalate to.

The bytecode removal, privilege drop, and env stripping are just there to make the agent's life harder if it tries to inspect its own runtime. Not the security boundary.

Re: Building secure, scalable agent sandbox infrastructure

#13

I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?

Agreed, the pattern is converging across the industry. The Unikraft setup is where it gets interesting for us with sub-second boots (or sub 100ms even), scale-to-zero that suspends the VM after a few seconds of idle (frees resources), and dedicated bare metal in AWS so we're not sharing hardware.

We haven't open-sourced the control plane glue yet but it's something we're thinking about. browser-use itself is open source. The sandbox infra on top is the proprietary part for now.

Re: Building secure, scalable agent sandbox infrastructure

#14
This resonates. Pattern 2 (full agent isolation) handles the runtime threat, but there's a gap upstream. The MCP ecosystem has thousands of servers now and zero vetting. You find a repo, hope it's legit, and give it system access. Sandboxing won't help if the tool itself is designed to exfiltrate data through legitimate-looking API calls.

The missing layer is pre-installation scanning. Runtime isolation + supply chain vetting together is the real answer.

Re: Building secure, scalable agent sandbox infrastructure

#15
post #9
post #8

The billion engineers building sandbox tools at the moment are missing the point. Sandboxing doesn't matter when the LLM is vulnerable to prompt injection. Every MCP server you install, every webpage it fetches, every file it reads is a threat. Yeah you can sit there and manually approve every action it takes, but then how is any of this useful when you have to supervise it constantly? Even Anthropic say that this do…

Yup. I just wrote about this last week: https://tachyon.so/blog/sandboxes-wont-save-you Of all the problems in agent security, sandboxing solves the easiest problem.

Excellent post.

Re: Building secure, scalable agent sandbox infrastructure

#17

I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?

I’m building a self-hostable, open source agent sandbox orchestrator here: https://github.com/ash-ai-org/ash-ai

Re: Building secure, scalable agent sandbox infrastructure

#18

I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?

Agreed, the pattern is converging across the industry. The Unikraft setup is where it gets interesting for us with sub-second boots (or sub 100ms even), scale-to-zero that suspends the VM after a few seconds of idle (frees resources), and dedicated bare metal in AWS so we're not sharing hardware. We haven't open-sourced the control plane glue yet but it's something we're thinking about. browser-use itself is open sou…

Exactly, this is the very stuff I'd be interested to hear more about. Great work on all this btw and best of luck going forward!

Re: Building secure, scalable agent sandbox infrastructure

#19

I think this is pretty standard and similar to approaches that are evolving naturally (I've certainly used very similar patterns). I'd be pretty keen to actually hear more about the Unikraft setup and other deeper details about the agent sandboxes regarding the tradeoffs and optimizations made. All the components are there but has someone open-sourced a more plug-and-play setup like this?

We are building a plug-and-play setup for this at superserve.ai
Post reply on HN